HackMyIP
← Back to News
2026-08-03 The Hacker News

PNLD Breach Exposes UK Police and Government Contacts on Dark Web

Data BreachPhishingCloud Security

The Police National Legal Database (PNLD), a service that provides legal information and products to UK police forces and criminal justice organisations, has confirmed a data breach that exposed police, government and customer contact details on the dark web. The compromised dataset included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident was identified on July 26, and as of August 3, 2026, PNLD had not publicly disclosed the number of affected individuals, the intrusion timeline or the volume of data exfiltrated. The service stressed there is "no evidence to suggest that passwords or other security credentials have been compromised," and clarified it is not connected to the Police National Computer, the Police National Database, or any crime-recording system.

The breach also exposed some names and email addresses belonging to people who had submitted questions through the public "Ask the Police" service. UK government guidance warns this raises phishing risk, since attackers can now craft messages referencing or appearing to originate from named officers, making fraudulent outreach far more convincing. PNLD reported 108,429 police registrations and support for all 43 Home Office police forces in its 2025-26 annual summary, though the organisation emphasised that figure represents total user registrations rather than confirmed breach victims.

Technical analysis points to a Microsoft Power Platform misconfiguration as the likely attack vector. PNLD's 2023-24 annual summary disclosed the database runs on Microsoft Power Platform technology, and The Hacker News confirmed the breach-notice page references assets hosted on content.powerapps.com. Threat actor ExfilSquad claimed responsibility for 15 victims, and VenariX reviewed samples from 11 of them, finding Dataverse-consistent structures across every case. Researchers assessed the campaign-level path as a public Power Pages site granting broad Anonymous Users access to Dataverse tables, combined with an enabled Power Pages Web API or legacy OData feed, consistent with Microsoft's own documentation that the Anonymous Users role exposes table data to any site visitor.

PNLD has notified all affected organisations and the Information Commissioner's Office, and is working with the National Crime Agency and specialist cybersecurity firms. Affected Ask the Police users have already received guidance emails. Security professionals and members of the public can verify whether their details appear in known incidents using an email breach checker, test whether their browser is leaking identifying data via a browser fingerprint test, and run a broader privacy checkup to confirm their accounts are not inadvertently exposing organisational information.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →